Re: [Add] Fwd: New Version Notification for draft-reddy-add-resolver-info-02.txt

Ben Schwartz <bemasc@google.com> Thu, 08 April 2021 15:25 UTC

Return-Path: <bemasc@google.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A18B3A08D6 for <add@ietfa.amsl.com>; Thu, 8 Apr 2021 08:25:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -17.598
X-Spam-Level:
X-Spam-Status: No, score=-17.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 52YAMbiiwKyq for <add@ietfa.amsl.com>; Thu, 8 Apr 2021 08:25:29 -0700 (PDT)
Received: from mail-wm1-x32a.google.com (mail-wm1-x32a.google.com [IPv6:2a00:1450:4864:20::32a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 750683A08C0 for <add@ietf.org>; Thu, 8 Apr 2021 08:25:29 -0700 (PDT)
Received: by mail-wm1-x32a.google.com with SMTP id y124-20020a1c32820000b029010c93864955so3150944wmy.5 for <add@ietf.org>; Thu, 08 Apr 2021 08:25:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=gOo5EE8ZmHIVzZhUdy29DV6W9HYetNCCl1Cpfpe2U0I=; b=HH6aylwoIV3xVCzKad8ujTKxIrcuZvPYpo5KB2Rc/8096thS36Mvozkx9cAyxwSlc3 m4EpcIHH4MOyO+eGpeHDgRxy5fjfYGb813sc91ZZ+ZT2J3QQ68K8DXU3tYSpqVdmSZOI COe7DCubhXSTykJXZOsnNTAqasJ5qP115uZcQG62PCouV6CelRoBmDZW+vhl9OW9962D KSN4APp6phZkDkrVrbz/vRVJ9i8WwQ4d1OsucQupnMIRxWDCV+A90NLItgqCW6D4k8bt AuOgWsXNJfE3M7ii4MUeMsiJF/toVTCOAJdv9tYIvYhs2wyQU1pPfMIWGRf0a0Q/idQ1 BHpQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=gOo5EE8ZmHIVzZhUdy29DV6W9HYetNCCl1Cpfpe2U0I=; b=IZnVT/J3HY4fL9n3/xKxLVerILpeKi9KerSyqAT08OB8mgvi3dt6FEB6/fbhvWZI0g PsYYQIHxPwBwVCKkq8XCCKv5sz3cquXjgKrmwDrts7v3vKTJ+GOPSQgr60F0BXafv2Wj dgL7oGmjJ6Q5UI3+GhCBWOf9NKxX2dwmWjDVDbmSFy6VVq/a18tr4o6wosWpgjwY4pH4 pqlOsz/3zPJqvnNv6fu8TfKyKZ+k/7ICuAu3eJxdvoD3WYciHYbyS9JaCgU+XBY0s2By 9Wum73xq8wNYeMDGkl+Vw1gPu5MBonzHil+Fm/nppprrDrDM+O0cxeow0B9CjcDioDsM BwTg==
X-Gm-Message-State: AOAM531R/0CLL02nfqsAVNumgV2b1tvmrim94CCpdPVGxbj1mVbUJOIt mNp0Bj86RPNbt/O3YhYIEGB+q7bEJ8hyRVLXaYAMeA==
X-Google-Smtp-Source: ABdhPJx/XZliO+ZJvPmP31cxvAUwYuX0+N8VLjALfDTHDutyKw0ZcwinA4BmlogiNH/DGLhjeMYQKEz4LNVFRcoNjUA=
X-Received: by 2002:a05:600c:3541:: with SMTP id i1mr9115533wmq.97.1617895527183; Thu, 08 Apr 2021 08:25:27 -0700 (PDT)
MIME-Version: 1.0
References: <161761144355.1534.1189126958533352034@ietfa.amsl.com> <CAFpG3gc6ri4eiM-iOdUyp+BEQtqx8VA773nyv3H-Csmm3t77=A@mail.gmail.com> <194e9a5a-6ab-e77d-eb9b-7c341a02639@dotat.at> <CAFpG3gce9_B2LYUs4+TKrpa8bRQh5zsFKg8+459cwpVuOwvLEw@mail.gmail.com>
In-Reply-To: <CAFpG3gce9_B2LYUs4+TKrpa8bRQh5zsFKg8+459cwpVuOwvLEw@mail.gmail.com>
From: Ben Schwartz <bemasc@google.com>
Date: Thu, 08 Apr 2021 11:25:15 -0400
Message-ID: <CAHbrMsDV1dYC_4jnqXZSGYJnMJQezEvCTvwyhOPji9YF3QsHQA@mail.gmail.com>
To: tirumal reddy <kondtir@gmail.com>
Cc: Tony Finch <dot@dotat.at>, ADD Mailing list <add@ietf.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-256"; boundary="000000000000339bcb05bf77a8d1"
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/6tSu0kk7zks4HhCC69EZU7mS8Ew>
Subject: Re: [Add] Fwd: New Version Notification for draft-reddy-add-resolver-info-02.txt
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Apr 2021 15:25:34 -0000

On Thu, Apr 8, 2021 at 5:40 AM tirumal reddy <kondtir@gmail.com> wrote:
..

> For example, if the special use domain name "resolver.arpa" is used to
> discover the Encrypted DNS server, the client can first query the resolver
> for SVCB records for "dns://resolver.arpa" to get the fully-qualified
> TargetName and then retrieve the resolver information using the RESINFO
> RRtype, QNAME of the TargetName.
>

I don't think this is a good design.  It does not add security, and having
multiple places to look for RESINFO records seems likely to add complexity
and reduce interoperability.

The DNS resolver information can be retrieved after the encrypted
> connection is established to the DNS server
>

This seems like a much better approach.

Of course, if the resolver is known by name (resolver.example), then it can
simply publish a RESINFO record on that name.